-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: s390x Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (ziehrer) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: 5d813d214e697c6bba4a44d2d51e12ab7012b62d 20612 jq-dbgsym_1.7.1-6+deb13u3_s390x.deb 2aea44b243fcc4956c1122efc2ed9f53854c49e5 7630 jq_1.7.1-6+deb13u3_s390x-buildd.buildinfo 05a23dded6000a07091d5841e5186147df89490b 79668 jq_1.7.1-6+deb13u3_s390x.deb 2d025c0a4f562b38caa46accfc08943b9e6055ae 25704 libjq-dev_1.7.1-6+deb13u3_s390x.deb fff1e579677c25d7cc82bd003dd6579b993d0af6 431012 libjq1-dbgsym_1.7.1-6+deb13u3_s390x.deb b737f8e0b640192c9ece801917fdc7db15113940 189888 libjq1_1.7.1-6+deb13u3_s390x.deb Checksums-Sha256: f1aced55c6c08838b6e3ca791f19fca63a5d348056dee8d240aa2c0f06ce0d82 20612 jq-dbgsym_1.7.1-6+deb13u3_s390x.deb b2db61ce3a3a89967c5c99b9587508f8d9889a8b21c923beb216f4cb44c61099 7630 jq_1.7.1-6+deb13u3_s390x-buildd.buildinfo f5e2d682aa33572c5a4e19b7878a0a83eab9ab707c9570cb6b5e1454fd981748 79668 jq_1.7.1-6+deb13u3_s390x.deb 3e8e089f23884bda41fd67f60fb9548073bbec6c2da0a2ee214ccdfaa12aa828 25704 libjq-dev_1.7.1-6+deb13u3_s390x.deb a689d788a42917aa0dc3a9c3378e342e90b2ffc27fb6928ac55dcc263be3bfe1 431012 libjq1-dbgsym_1.7.1-6+deb13u3_s390x.deb 55c8c714c1ccb20381af0a7732737410dfcf3d17903afcc75d8a80be11cefe92 189888 libjq1_1.7.1-6+deb13u3_s390x.deb Files: 63816f1552ce3dc76d0e3e4f0885e835 20612 debug optional jq-dbgsym_1.7.1-6+deb13u3_s390x.deb 8ba434689df6f4df30f66327f025223f 7630 utils optional jq_1.7.1-6+deb13u3_s390x-buildd.buildinfo 7a1780decb1603baa887bea13d85f839 79668 utils optional jq_1.7.1-6+deb13u3_s390x.deb 10a262016bddc36411cfddeafaa99592 25704 libdevel optional libjq-dev_1.7.1-6+deb13u3_s390x.deb 02c51a3a2c096d3b7f23cabfa6ed436b 431012 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_s390x.deb 961bc56f2ac7be883f663f36d70e95ff 189888 utils optional libjq1_1.7.1-6+deb13u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmp0MGEACgkQMWUFebkH noQuyg/8D/hjVwwRjBKKVPzpoQXiXxZItoFwU00nd6z4mPJ+XLfeeJqpef5DOYfb wIqPg+6wrE2l4xm5dSf6EBCOGAvK7rU5eR2KktV5Osj0Hk61XDvxWJlhdY1nEaid JL6bX0MTXBvNNt6PF08Y4eVCfpTNi9CLfX8ZK5M5hO7dqD6ARSxhWX4BHM+rLszq qLLsxIwhoxarG7XGg8lp586Bu8mYn57RtLvbtSnHY1mCgvfn1aOtxb7stT1kKL/a fz5E8s7LN4UNe5NZM5jh6F+uNZ36xyR1oy4vMsG+A/c/Fxa+64RLpoQD6HuyrsNH pCvk9oglBs0zeAdVWd53xfhZlo/Lx2tbUF+mhmlIH1zHnfdO+Zu3+W0p9Ofcsv7y YWYUHJCIltjS8UXAdDsuF3uk+m58akUiUeNEck0P+P02JR7WonAR1bo0+ALWPSR4 DMjNlYV8QdNOqnefeLEF5KNltQU4bV7N6ioJI0B7OMpECE6wVMJuQwtCHf5BGZj8 4DXnZe5CmmJLLoynOAAtFqGGS8WTnyb+8ifZdDwPiA4+z8Ap/9BiEU0g5K8f0SmE YWTnF+dr9PMGJgX8b/7gmAKCwpV8OogNwfyyE6AN5+24Xy2/goPSA4ZvgFlpk1+G M1YiBfAzdVmg2KxLLyWTNvEVruVgr1zKRMhr/sfaF6r/unLAaIQ= =tGQZ -----END PGP SIGNATURE-----